CVE-2024-38485: Medium severity dell emc elastic cloud storage vulnerability
Published Dec 9, 2024
·Updated
Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.
Affected Software
2 affected components
Dell ECS<3.8.0
Dell Elastic Cloud Storage<3.8.0.0
Event History
Dec 9, 2024
CVE Published
via MITRE·02:46 PM
Data Sourced
via MITRE·02:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38485?
CVE-2024-38485 is considered a low-severity vulnerability that allows potential exploitations leading to sensitive information leakage.
2
How do I fix CVE-2024-38485?
To mitigate CVE-2024-38485, upgrade Dell ECS to version 3.8.0 or later.
3
What is the impact of CVE-2024-38485?
The impact of CVE-2024-38485 includes the potential for sensitive information leakage through redirection triggered by a remote attacker.
4
Who is affected by CVE-2024-38485?
CVE-2024-38485 affects users of Dell ECS versions prior to 3.8.0.
5
Can CVE-2024-38485 be exploited remotely?
Yes, CVE-2024-38485 can be exploited by a remote low-privileged attacker.